Angel Smith: Assume the Thief Is Already in Your House
Starts with a 20 minute pre-interview call. I handle everything else.
About this episode
Angel Smith is President of Global Public Sector at Virtru, and her argument is that perimeter security assumes you can keep the thief out of the house. You should assume he is already inside, and protect every individual data object instead of the wall around it. She spent 23 years in the Marine Corps, first on aircraft radios and then flying C-130s, before the House Permanent Select Committee on Intelligence and eight years at Microsoft.
She explains why Virtru open sourced its Trusted Data Format rather than holding it as proprietary IP, traces the idea back to 9/11 and the way governments still share data, and makes the case that bad data going into a model is a bigger risk than data leaking out of one.
In this conversation
- Why perimeter security fails once you assume the attacker is already inside
- Why Virtru open sourced its own Trusted Data Format instead of keeping it proprietary
- What 9/11 has to do with the way governments still share data
- Why bad data going into a model is the bigger risk, not data leaking out
- How data clean rooms let rivals and allies collaborate without giving away the jewels
- Twenty-three years in the Marine Corps, and what carried over
Full transcript
Welcome back to another Agentee Digital podcast. Uh today I'm joined by Angel Smith, the president of Virtru. Uh Angel, it's great to have you here today.
>> It's nice to meet you. Thank you so much. >> So for uh listeners that don't know Angel Smith, uh who is she and uh what does she do?
Um, so I was uh I I was a Marine for about 23 years. I started out enlisted and I was a communications technician. So I worked on uh radios and you know things like that uh for aircraft and uh dask vans like kind of like the air control vans.
Um and then I became a pilot. I I flew uh C130s for the Marine Corps. Retired in 2016 and I went over to Capitol Hill for a few years.
Um, I worked on the military intelligence portfolio there. Uh, I was working for with the House Permanent Select Committee on Intelligence. Then I went over to Microsoft uh for about eight years.
I worked um inside of I started out over in the um uh government affairs division and then moved over to mission engineering. And after mission engineering, I ended up moving into uh their global defense team. And uh while I was there just this last January, I was asked to come over to work at Virtru.
And as the more I became more familiar with the product, the more I was like, "Oh my god, this solves so many problems, so many mission problems across the entire department." And so uh I jumped on the opportunity to come over to virtue. So yeah, so that's it. >> Yeah.
>> And uh can you recall something that uh you learned from the days that you were flying that uh maybe transferred into business? Yeah, in some shape or form. >> Yeah, for sure.
Especially on the tech side. We, you know, I was the type of platform that I flew. I flew C130s and we were very, we were all over the world all the time.
And um when you would leave outside of your base and station, it was you really had to kind of figure out like the communication, the technology, you had to figure out a lot of things on your own. And we were often working with international forces. we were often working in disconnected environments and things like that.
And because of that, it's it really makes your life orders of magnitude more difficult. And the other thing too is that you start to figure out, you know, you start to do whatever you've got to do to get the mission accomplished. And that was that's super informing.
I used to listen to a gentleman named uh a really good friend of mine, his name is Dave Abba. He's a who's a he's retired major general out of the Air Force. and he tells this really interesting story about F-35 pilots from two different countries.
Uh, and they were the US and I think Norway is the example he was using and they were essentially using WhatsApp to do mission planning on this like the most sophisticated aircraft on the planet, but they're using WhatsApp because that's the best that they had. And like that as much as you know people kind of start to throw stones at them for that, it's actually kind of like well >> this is not their fault. We like we have done this to them.
like they they don't have the technology that they actually need that is in a lot of cases more readily available and commercial. But we've put our the people that fight wars for us across the entire world at a technological disadvantage just because it's a trust mostly a trust problem more than anything else. um which is you know disappointing but this is one of the things that I saw so much so much benefit out of a company like Virtru that I left my amazing job at Microsoft working around amazing people to come to this you know small startup because it was like oh my god this is this is transformational so um yeah so I don't know that's helpful but yeah >> yeah yeah and and so uh what does virtue do for for people that are unaware of uh what what does virtue do?
>> Yeah. >> What are you best at? >> Yeah.
So, virtual is a datacentric security company. So, kind of at a high level, the way you should think about it is, you know, typically the way that you protect data is perimeter security. So, you know, think about people always put up firewalls and you know, things that surround data in a specific environment.
Virtru believes that as a company we believe that's insufficient and you have to actually perimeter security is important but protecting the data independently every single data object within every environment is equally as important like we have to we've got to protect every single data object because every single data object you have to assume that your perimeter has already been breached and you've got some type of a bad actor toodling around in your face. If you assume that, then you change your posture. And as an example that I like to use is let's pretend that you've got a thief that you know is living in your house and walking around.
You can't see them, but you know that they're there. Um, and they're just going to slowly start to like pick off things inside your home. What would you do differently with all of your valuables if you knew that there was somebody in your house looking for them?
would you behave differently if you knew they were? That's kind of the perspective that we have is we are assuming we have a thief in the house and we are protecting every single piece of data um in order to be able to make sure that we're protecting the most most valuable pieces of data that we've got. Does that make sense?
>> Yeah. Yeah. >> Yeah.
What I found interesting about virtue is uh that uh you built TDF as an open standard >> and then you actually open sourced it, right? And so uh I feel like in a space where everyone uh does proprietary lock in uh it's it's uh it's different. So why uh virtue gave away the standard?
>> Yeah. So to answer that question you we have to kind of go back and do a little bit of historical uh discussions about where Virtru was at a few years ago. And so when Virtru first started um well actually go back to 911 as an example.
So the two founders of the company are brothers John Ackerly and Will Ackerly. Both of those brothers um one of them John Ackerly worked over in the White House on the policy front and then Will Ackerly um who is a thousand pound brain was working over the NSA and they both saw 911 and the problem from kind of two different sides of the same wall. Um and it became very very clear to both of them.
The great tragedy of 911 was that all of the information and data that we could have stopped that attack from happening, we we had all of it as a nation. We had all of it. Um but there was no meaningful way for us to be able to get access to it.
And so, you know, Will and John, you know, both of them working inside the administration and inside the the intelligence community at the time, both of them saw this as a problem that was super correctable with the right technological solution because the bottom line was is like, you know, to go back to the the trust discussion. Um, the trust comment from earlier, this is a trust problem. These are a bunch of agencies inside of our own government.
And then if you you can magnify that across the entire world. It's it's we have data in so many different ways is actually the most valuable resource that most of us have. Just openly sharing a lot of that information is just it's it's a difficult thing to kind of let go of.
And so the theory was if we could create a software solution that created trust around every single piece of data that secured every single piece of data and then you could use Aback controls on both sides of the data and the user front. You could fundamentally change the way that we ch we used and shared data across the board. You could change everything.
you could get everybody to share more, especially if they had a level of confidence in knowing that who you give it to is exactly who you expected it to have. And then another, you know, component of it that um I think we, you know, we learned the hard way with with leaking. leaking is an interesting problem.
And I'm gonna bring up this is probably a little bit controversial, but um when you think about something like Snowden, part of the Snowden problem wasn't necessarily that he stole so much intelligence, it was that he took a lot and we don't completely and fully understand exactly what he took. So that's a whole another set of problems. you've got this one problem essentially saying like look I I I need to protect my data at least creating some type of a mechanism that would maybe create a deterrent.
The second component of it that's incredibly important is being able to have an auditable log and trace of everything that has that that particular individual has ever accessed anywhere it went. And then in some cases in the in the time of AI, let's say that hypothetically, you know, we I'm going to introduce kind of a different concept. Um, in the time of AI, one of the things I tell people pretty regularly is we're very very focused on Xfill of data as the greatest threat.
I think we should pay attention to infill of data. And when you think about large language models, they it's a crap in crap out scenario. So, if I was a bad guy, I'd probably be less concerned about taking and more concerned and more motivated to add garbage into the system.
>> So, that way I would throw off all of your results and everything that's coming out of an LLM or whatever, you know, AI model that you're using. I can skew your results and create really, really, really unorthodox responses based off of um whatever type of data that I've been able to manipulate. So, um, I I think that there's there's a couple of different components of it that kind of got them started and where we find ourselves today is in a completely different place where they were at when they started the company six I think you know 15 16 years ago.
Now we've got LLMs and what we're seeing is that if you take a dataentric approach it you have as much control in the LLM and AI space as you did when we didn't have it. But you have to be motivated at the data layer. You can't the perimeters I don't want to I'm not going to say that perimeter security is dead because perimeter security is 100% a component.
>> But you have to have both if you really want to be able to survive. I think in today's um as as the as technology is starting to to I mean just absolutely escalate and how quickly it's starting to come out, we have to have a completely different perspective on how we're protecting things. H how do you use uh AI and virtue specifically?
>> Yeah, so we have a couple of things. So when I I know I had mentioned just a second ago aback controls. So um so it's access um access specific access for a particular piece of data.
So you're giving an attribute to data and an attribute from every single person that might actually access the data. If the data doesn't have an attribute and you don't have an attribute that gives you access, then that data can't be utilized. And so we've built um a capability that would essentially if you Aback or you TDFed every single piece of data, it would not it has to be TDF before it could be used by an LLM.
Um so a TDF is trusted data format. So we essentially say wrap everything that you possibly have. And if you wrap it, then you know that it's valid.
So when it goes into any type of an AI engine, you have certainty that that you're not, you know, you're not pulling a bunch of crap in and getting an output that you, you know, you're not aware of. And that's this is especially important when you, you know, I hear a lot of people go, "Yeah, but you have that same control um if you're just allowing people to pull using an LLM in their isolated environment. Well, what you're assuming is that you have no adversaries in that environment.
If you take a completely different perspective and you go to the data layer and you make the only confidence you actually have is that every single piece of data inside that environment is actually uh TDF or trusted data format is wrapped around it. So you know that everything I'm fitting into that model has been approved or authorized and it's it's no it's clean data for a clean output. So that's kind of where we see probably our greatest contribution in the AI space is just making sure you get rid of the crap in crap out.
You can validate what's going in and you can validate that the outputs that I'm getting. Yeah, >> this is especially important for I think defense and intelligence agencies that are making you know life and death decisions about operations and um it gives them a level of confidence that what they are making if if they start to use this in the the udaloop cycle that the decisions that they're making are no kidding these are valid decisions there's not untrusted data being utilized they can they confirm that I am getting no kidding good feedback based off of accurate data and I can have confidence in whatever decision that I make in a battle space. >> Mhm.
What do you think is the most common mistake uh that uh you see agencies make when they think that they have solved uh data sharing for coalition operations? >> Oh, I don't think I've seen anybody who thinks they've solved the problem. Um, I think everybody knows it's a problem.
Um, everybody knows we don't share enough. There's a really funny story that um that uh we've got a gentleman named Jim Hawkenhole that we've met with quite a bit and he tells the story about how he put a briefing to I think it was Jim Hawkenhole, but he put a briefing together um sent it over and by the time it had gone through all the different approval organizations, it ended up getting labeled as no foreign and so he couldn't even brief the document that he produced >> which is insane. Like he wrote it.
So, it's really funny. Um, I think that this is a this is something that especially on the five eye side, they're working very very hard to try to figure out. Um, but this is a this is an area that I think that everybody understands that we've got a big problem with data sharing amongst nations.
Sovereignty is also a huge thing. And so like as so much I'm talking about the defense and intelligence space, the reality is is that we've got equally as bad a problem on the commercial side. You've got, you know, companies that are worried about IP protections.
Um, you've got, you know, this is you, you know, like, uh, I'm going to use BAE as an example. BAE is a company that's got, you know, nodes all over the world. They're sharing IP.
They're selling to foreign governments. They they have the same type of data protection problems. healthcare industry is really interesting as well.
We started doing quite a bit of health care work with some of the IND um with u cancer clinics that are trying to solve can you know how to find a cure for cancer. um these hospitals all have their own special and unique IP >> that they want to share data with other universities but they don't want to give away the jewels right and so they're essentially we're creating these data clean rooms for them so that way everybody can kind of dump the data in they can query against it but they can't find root source data based off of you know based off of it so it gives them you know levels of protection that their IP is protected but these universities can still collaborate with each other to try to find a cure for cancer and you're starting to see some really interesting um findings come out of this particular type of practice and so you can kind of see it across the whole world. It's collaboration amongst nations but it's collaboration between you know university hospitals between defense industrialbased companies between anyone who does work across the globe like global uh global collaboration is actually a real has that this has been a problem that's been in the ecosystem for a very long time.
So this is kind of technology that was born in the IC has started to go to commercial coming back to defense and I could see it scaling into commercial again once we kind of get going. >> Mhm. And uh what's next for Virtru uh now that you've been in this seat for uh what seven months I believe.
Uh >> yep. Yep. Just about seven months now.
Um we are really starting to kind of get our feet underneath us. I lead the the global public sector team. So, uh, we're pressing super super hard on trying to make sure that we've got partnerships with, um, making sure we're enabling NATO, making sure that we're enabling the five eyes nations, um, making sure that we're working with some of the defense industrial based companies very, very closely so that way they can share trade.
You're seeing really interesting programs like the GCAP program. That one's fascinating because if you're familiar with the GCAP, it's that's the sixth generation fighter aircraft. It's nextgen fighter 4.
It's being built by uh BAE, Leonardo, and Mitsubishi Heavy Industries. Three different nations, three different companies that are kind of like taking the lead. Um, amazing opportunity, but that's like kind of that kind of epitomizes the problem when you've got three different companies collaborating together, kind of all a little bit competing with each other a little bit.
Um, we're trying really hard to kind of get in there and show that we can we can really help you guys um, share data more quickly. If you look at the way that we share data on some of these large programs right now, it's more defined. Um, it's it's like save it on a disc or save it on a thumb drive thumb drive, hop on an airplane, fly across the world, share the data, then do in reverse.
It's it's very like we call it in the US we call it sneakeret. Um, because you're having to walk it over. Um, so, uh, getting past sneakeret to be able to move delivery timelines left is super important.
>> Um, we we should be able to crank out large hardware end items orders of magnitude faster than we do, >> you know, 5 years ago, even today. We should be able to make make this like much much faster. So I think with with what's next for virtual at least on the public sector side really getting super deep into uh the ecosystems um that are important for the public sector business and on the commercial side the ecosystems that enable the commercial sector.
So that way we can bring them, you know, some technologies that will make them operate faster, more securely, protect their IP, but give them opportunities to be able to accelerate um to the max extent. >> Okay. And uh wrapping this up, I want to ask you uh what would you like the listeners to take from this uh episode and where can people find you?
>> Well, yeah, you can you can Google search us. We are easy to find on virture.com. So, please, you know, come uh reach out, let us know if you've got any needs that you need solved.
I would say if I could leave people with one piece of information, one one piece of thing to contemplate is protect the data at the data source. Think about security from a different completely different lens. I I sometimes say we have to throw the baby out with the bathwater right now.
We've got very very very motivated adversaries out there that are super focused on trying to figure out how do they undermine every average everyday citizen. And um I think the virtue perspective and granted I'm biased here but I think the virtue perspective actually really does apply to everyone. When I think about like my mother who is, you know, in her late '7s, vulnerable to, you know, spamming and things like that, I would love to be able to put her in a position to have some type of like reasonable protection because what we're doing right now is creating orders of magnitude more more vulnerable populations and there are very few things on the data side that are sacred and I think that uh virtue can really help there and it's it's a new day.
Think about this, think about security differently. >> Okay. Well, uh, thank you, Angel, for, uh, coming on to the podcast and sharing your thoughts.
>> Thanks, Mikulas. It was a great meeting you.
Grab a slot and we will record.